Esm Relnotes p45 Sp2
Esm Relnotes p45 Sp2
ArcSight™ ESM
Version 4.5 SP2
Revision History
02/01/10 ArcSight™ ESM Updated the Oracle CPU and OPatch to reflect the
Version 4.5 SP2 January 2010 release of the same. ESM v4.5 SP2 got
certified with the Jan 2010 Oracle CPU
01/18/10 ArcSight™ ESM Release Notes for ArcSight™ ESM Version 4.5 SP2.
Version 4.5 SP2
E-mail [email protected]
About Platforms
Please see the official ArcSight Product and Platform Lifecycles document for a complete
and definitive list of supported platforms for each component.
update translation packages for Japanese, Traditional Chinese, French, and continue
support for Simplified Chinese
address customer requested and other issues
Updates for geographical information and vulnerability mapping
provide Oracle CPU certification with currently available CPU of January 2010 Update
If upgrading from an older version of ESM, you are required to upgrade to all
the interim versions one at a time, before upgrading to v4.5 SP2.
For example, if you are upgrading from v4.5 GA to v4.5 SP2, you will be
required to first upgrade your v4.5 GA installation to v4.5 SP1 before
upgrading to v4.5 SP2. See the Upgrading ArcSight ESM from v4.5 GA to v4.5
SP1 document for details on upgrading to v4.5 SP1. After you have upgraded
to v4.5 SP1, see the Upgrading ArcSight ESM from v4.5 SP1 to v4.5 SP2
document to upgrade to v4.5 SP2.
Forwarding Connector
The ArcSight Forwarding Connector lets you receive events from a source ESM Manager
installation and send them to a secondary/destination ESM Manager, a non-ESM location,
or to an ArcSight Logger.
This release supports both FIPs compliant and non FIPs compliant versions of the
Forwarding Connector (ArcSight-4.7.6.5416.0-SuperConnector).
Please refer to the SmartConnector Configuration Guide for ArcSight Forwarding Connector
for more information.
Usage Notes
Please review the following points to ensure smooth operation.
Case Customization
The data type used for case stage has been updated to be of enumeration data type
instead of the String data type used in previous ESM releases. So, if you had Case queries
in your system that used string operators on the Case Stage field (for example "stage
startsWith 'F'"), you will be required to manually fix those conditions to use operators valid
on enumeration data types. For example, if you have a condition "stage startsWith 'F'" and
there are two possible enumeration values (2, Final) and (5, Follow-up), you should change
the condition to "stage = Final or stage = Follow-up".
Also see bug “51112” on page 17 for other notes on this topic.
ESM v4.5 SP2 does not support plotting the chart component for reports generated in the
CSV format. But, adding this property in the server.properties file:
report.csv.header=true
will add reportName, startTime, endTime, and timeZone information to the CSV report.
If you need a chart, you can generate the report in PDF format.
Starting in ESM v4.5 SP1, Active Channel queries use dynamic sampling level 2 instead of
level 4. (Level 4 was the default in ESM v4.0 SP3) The level has been changed because of
a bug in Oracle optimizer that sometimes causes the time spent in sampling to be very
high, slowing down the overall channel.
For reports, trends, or any other queries, the dynamic sampling level continues to be at
level 4.
If you observe any query performance issues, refer to the ArcSight ESM Administrator’s
Guide topic on “Query and Trend Performance Tuning” (under “Troubleshooting”). Try
those troubleshooting recommendations about regenerating event statistics, and so forth.
If the performance issue is still not resolved, contact ArcSight Customer Support for help.
1 Enable ArcSight systemuser by running the following from the Manager’s bin directory:
arcsight configsystemuser
2 When prompted, set the External ID and password for the systemuser.
Important:
The External ID must be identical to the user ID set for your Active
Directory/LDAP account.
The External ID should not contain a space.
3 Log into the Console with username systemuser and the password set in the above
step.
4 Stop the Manager by running the following from the Manager’s bin directory:
arcsight managerstop
5 Restart the Manager by running the following from the Manager’s bin directory:
arcsight manager
6 Start the Console and log in with username systemuser and your password which is
linked to the Active Directory/LDAP account.
Vulnerability Updates
This release includes recent vulnerability mappings (December 2009 Context Update) for
these devices:
Snort / Sourcefire SEU 281 Bugtraq, X-Force, MSSB, Faultline, CVE, Nessus,
MSKB, CERT
Cisco Secure IDS S457 Bugtraq, X-Force, MSSB, Faultline, CVE, Nessus,
MSKB, CERT
Windows 32 p9169457_10204_Win32.zip
Windows 64 p9169460_10204_MSWIN-x86-64.zip
(AMD64-EM64T)
Linux 32 p9119226_10204_Linux-x86.zip
AIX p9119226_10204_AIX5L.zip
Solaris 64 p9119226_10204_Solaris-64.zip
OPatch
Visit the ArcSight Customer Support product-download site to get the correct Oracle CPU
package and OPatch for your environment.
Linux 32 p6880880_102000_LINUX.zip
Solaris 64 p6880880_102000_SOLARIS64.zip
Windows 64 p6880880_102000_MSWIN-x86-64.zip
(AMD64-EM64T)
Windows 32 p6880880_102000_WINNT.zip
AIX p6880880_102000_AIX64-5L.zip
Download the correct Oracle CPU package for your platform (see the tables
above) and unzip it under your working directory.
Download the Oracle 10g OPatch file for your platform.
2 Install the OPatch:
5 Read the next section in this document, “Workarounds for Known Issues in Oracle
CPU” on page 6.
6 Install the CPU (that you downloaded in Step 1) according to the steps outlined in the
README in the CPU zip package for your platform.
where $ARCSIGHT_HOME refers to the location where you have installed the ArcSight
Database.
For example,
On Windows:
>OPatch apply
On UNIX:
8 To complete the installation, follow the “Post Installation Instructions…” steps in the
README.
This error occurs when there are other processes running that lock the file in question. The
processes that cause the lock might be related to Oracle. As a workaround, reboot the
machine and try the patch application steps again.
1 Log into the database machine as the Oracle software owner (by default, Oracle).
2 Shut down the Oracle database, the TNS Listener, and all other Oracle services (if
any).
cd $ORACLE_HOME/rdbms/lib
Restarting the database server enables the ArcSight Database to utilize the extended
memory. Oracle cannot restart if this procedure is not followed. If the above
commands display errors, call ArcSight Customer Support. If you are using your own
Oracle software license, contact Oracle.
Upgrade
Number Description
ArcSight Manager
Number Description
47455 The notes associated with a package were not exported when the
package was exported.
The product software has been enhanced to export notes associated
with a package when it is exported.
54437 When the ESM Manager Asset belongs to a Customer Network, the
customer URI field in the events received from the connectors and
the correlated events generated on the Manager for the customer
network would be overwritten.
The product software has been updated such that the customer URI
is not overwritten.
56812 On Red Hat Linux 5.3: After rebooting the system, the Manager,
Web, and Partition Archiver services did not start automatically.
This issue has been fixed.
Number Description
59366 An ESM Manager would not start up if the "Device Asset Auto
Creation Controller" filter was modified such that it contained one or
more "Device Zone != <IP_address_range>".
The product software has been updated to address this issue.
Modifying the filter does not prevent the Manager from starting up.
ArcSight Console
Number Description
52792 A search operation was not limited to the specified resource types
when the operation was run from the Search Field on the Console
tool bar.
The product software has been updated to address this issue. Now,
the search is limited to the selected resource type.
53737 When a user tried to modify a case while a case channel was open
and sorted based on an Integer field, such as case id, a java
Runtime Exception occurred.
This issue has been fixed.
55907 Some drop-down menus would not work as expected on the ESM
56560 Console running on Mac OS X. For example, left-mouse button
would not select the item, but the right-mouse button would.
The product software has been updated such that the menus work
as expected on Consoles running on Mac OS X.
Number Description
56093 When a user tried to modify a case while a case channel was open
and an inline filter was applied to the channel, a java Runtime
Exception occurred.
This issue has been fixed; however, after modifying a case, the case
channel should be refreshed.
See also, 61659.
58475 When a custom banner was used for the ESM Console login, the
"User Access Log" dashboard would display a "Login Failed for
user name <user_name>" status for a user who had successfully
logged in.
The product software has been updated to address this issue. The
login status is correctly displayed for custom banner ESM Consoles.
59099 In ESM v4.5 SP1, when the user account of a recipient of a report
(sent through e-mail) was deleted, the remaining recipients of that
report were not displayed in the drop-down menu of the "Email to"
field in the Report Parameters tab.
The product software has been updated to address this issue. The
remaining recipients are now displayed as expected.
59310 If all fields of an active list referenced in a filter were not mapped in
the filter definition, the mapped fields were not displayed in the filter
editor. (Note that the conditions specified in the filter worked as
expected, even when the mappings were not displayed.) If all fields
of the active list were mapped, the Filter editor displayed the
mappings.
The product software has been updated to address this issue. The
Filter Editor displays mappings even when only the key fields are
mapped.
Number Description
61512 The process of batch editing cases from the case channel now works
similarly to that of the case resource tree.
This issue has been fixed.
61545 Query Viewer did not support "Annotate Events" and "Show Event
Details" options.
The product software has been enhanced to include these options.
Analytics
Number Description
Localization
Number Description
ArcSight Web
Number Description
58051 Custom column names in an ArcSight Web Active Channel would not
display.
The product software has been updated to address this issue.
Pattern Discovery
Number Description
58178 When a snapshot was created for Pattern Discovery and values were
repeated in mixed case, it would sometimes fail with the following
error:
RuntimeError : Default Transaction builder sees repeated
supporter!
The product software has been updated to address this issue.
Number Description
51954, 52680, This release does not support spaces in install paths for the ArcSight
52690, 54003 Database, ESM Manager or ArcSight Web server. If there are spaces
in the install paths, ESM Database, Manager, and ArcSight Web
setup wizards might not work, and ESM Manager startup will
generate exceptions. This is an issue on all platforms.
Workaround: Please do not use spaces in ESM installation paths.
The default install paths (e.g., C:/arcsight/Manager) do not include
spaces. If you modify the install paths, just make sure there are no
spaces in the directory names. Dashes (-) or underscores (_) can be
used instead of spaces.
55853 The ArcSight Database installer does not include error checking or
validation per Oracle supported schema user naming conventions. If
the user names specified contain anything other than alphanumeric
characters, the ArcSight Database installer will prevent
create/recreate of the schema and display the following error code:
error ORA-00921: unexpected end of sql command
Workaround: For ArcSight Database install and schema setup,
please keep in mind that Oracle supports only alphanumeric
characters for database user names, and will not accept a dash (-)
or underscore (_) in these names.
Upgrade
Number Description
25121 If you used a custom logo for ArcSight Web, the logo may not show
up correctly when you upgrade ArcSight Web.
Workaround: Update the logo manually after you upgrade ArcSight
Web. See the ArcSight Web User's Guide for details on how to do
this.
Number Description
47206 During upgrade to v4.5 SP1, the “SSL Client Only” authentication
option gets selected by default. If you had set up your v4.0 SP3
Manager to use “Password Based and SSL Client Based
Authentication” method, the authentication method selected in the
upgrade wizard panel will still default to “SSL Client Only”.
Workaround: Make sure to change the authentication method back
to “Password Based and SSL Client Based Authentication”.
51319 For Oracle upgrades (e.g., from Oracle from 10.2.0.2 to 10.2.0.4),
the Arcsight Database installer prompts you to specify the path to
the directory where the previous ArcSight Database was installed
(Previous ArcSight Software Directory). This might cause some
confusion about whether users should specify the path to the
ArcSight Database or to the Oracle Home directory.
Workaround: The prompt to specify the path to the previous
ArcSight Database software is not related to the location of the
Oracle Home directory. This is simply asking for the path to the
ArcSight Database software installation (e.g., C:\arcsight\db). If
you don't have the previous arcsight database software directory
available, enter the path of the current arcsight database software
directory that you are installing to.
52394 File resources are not handled properly during ESM upgrading. This
results in unassigned file resources after the upgrade. For example,
.art files are created as new file resources in ESM v4.5 SP1 and get
new version IDs during the upgrade. The original files are stored in
the Files resource under the Unassigned folder.
Workaround: You can remove the unassigned .art files after an
upgrade, since they are duplicates. The .art files can be safely
deleted.
34527 The arcdt command cannot get session waits from the database.
Launching the command to get session waits will generate an empty
file. An example of such a command would be:
./arcsight arcdt session-waits -c 1 -f 10 -fmt html -sp -o
/tmp/ss.html
This is caused by an issue with the JDBC driver.
Number Description
55935 ESM Console upgrades from ESM v4.0 SP3 to ESM v4.5 SP1 do not
properly read the security and login property settings (SSL files). If
you run the upgrade and Console setup through to completion via
the install wizard, you will still have to re-run Console setup.
Workaround: Cancel the installation after the Console is installed,
and run the ArcSight Console Configuration Wizard to configure
property settings.
In <ARCSIGHT_HOME>/<Console_Build>/current/bin, run the
arcsight consolesetup at the command line. This way, SSL files
are read and the Console can configure correctly.
61714 On Unix only: When upgrading from ESM 4.5 SP1 Patch 2/Patch 3,
to ESM 4.5 SP2, the dbcheck script produces an error.
Workaround: Do the following before running the arcsight
dbcheck command:
1 Open a shell window and go to the Database’s
<ARCSIGHT_HOME>/bin/scripts directory.
2 Run the dos2unix dbcheck.sh command.
ArcSight Database
Number Description
53484 Certain reports run for several hours and then time out or fail with
the error message:
com.arcsight.common.persist.PersistenceException: Unable
to execute query: ORA-01555: snapshot too old
This occurs because Oracle is using a sub-optimal query execution
plan. In some cases, this can happen because of insufficient space in
the ARC_TEMP table as well.
Workaround: Set the report to query with a full scan database hint.
For more information, refer to “Reports that query over a large time
range with complex joins take a long time to run” section in
Appendix B of the ArcSight ESM Administrator’s Guide.
56718 The dbcheck utility fails to create a .zip file for its logs on Windows
as indicated in the upgrade guide.
Number Description
ArcSight Manager
Number Description
17714 When a non-admin user runs a report, the report shows assets and
cases even though a non-admin user does not have the rights to
view the assets or cases.
33337 If the Send Logs utility detects that you do not have enough disk
space to upload the logs, it displays an error that tells you to free up
the disk space and retry log upload.
Workaround: Exit the Send Logs utility and restart it after freeing
disk space on your machine.
Number Description
42730 You cannot move an asset using Auto Zone if the asset is locked.
43678 If the search index file becomes corrupted, the Search index will be
out-of-date and the following message appears in the Manager log:
[ERROR][default.com.arcsight.server.search.index.IndexRes
ources][_init]
java.io.IOException: read past EOF
Workaround: Regenerate the index by issuing the following
command from the Manager <ARCSIGHT_HOME>/bin directory:
arcsight searchindex -a create
47345 The index updater uses roughly the same amount of memory as the
Java Heap Memory size, which could cause your system to
potentially run out of memory.
Workaround: Make sure to set your Manager’s Java Heap Memory
size to less than half of the physical RAM available on your system.
50794 In a hierarchical Manager setup, the base events for only some of
the correlation events get forwarded to the upper level Manager, and
this behavior is not predictable. If the upper level Manager needs
the base events for these correlation events, and the base events
are not present on the upper Manager, the base events get fetched
on-demand when the user opens the correlation event in the event
inspector panel on the upper level Manager.
51053 In some older versions of ESM, you may see some negative
timestamp values in the server logs. You will see an error that
begins with “java.sql.SQLException: BC date found in...” in
the logs. The resources for this error are not loaded.
Workaround:
1 Set the following property in the
<ARCSIGHT_HOME>/config/server.properties file:
server.date.correction.recoverFromBCDate=true
2 Restart the Manager.
Should this issue occur, notify ArcSight Customer Support so that
they can investigate its cause within your setup.
Number Description
51112 Stages resources are editable from the ESM Console, although these
should not be moved or customized. (See ESM Console Navigator >
Stages resource tree.)
Please keep stages provided as standard content in the given folders
and do not move them into another folder. Standard content stages
are Closed, Final, Flagged as Similar, Follow-up, Initial, Monitoring,
Queued, and Rule Created. (For more information, See the
“Standard Content” topic in the Console Help.)
51134 ESM integration commands launched from a chart view cannot pick
up attribute values from the chart (as they can from grid views).
For example, launching a URL integration command from a chart
view in an Active Channel or Query Viewer results in a popup dialog
asking for parameters values.
This impacts ESM-TRM (Threat Response Manager) integration
commands, as well as other third party integrations.
Workaround: For this release, limit deployment of integration
commands in the Console to chart views or inform Console users
that they will need to manually type in parameter values when they
run these commands from chart views.
55969 On Linux only: The ESM Manager CPU utilization is higher than
expected and impacts performance.
The Manager's CPU utilization may become high especially in the
kernel CPU utilization area. This issue may be specific to your
system/hardware.
Workaround: It may be possible to fix this issue by updating
drivers or reinstalling the Linux operating system.
Number Description
61227 The -u resource is not an option for export, when running the ESM
archive tool with the following command:
arcsight archive -u <username> -m
<source_manager_hostname> -format exportuser -f
exportusers.xml
Workaround: The -u option can be used if the archive tool is run in
standalone mode.
ArcSight Console
Number Description
24496 Drill down from Event Graph data monitors to channels is not
supported when the Event Graph data monitor uses Variables to
retrieve or parse event information.
40627 In the standard field set for a channel, changing the Column Flip
Limit in the Preferences dialog does not take effect after clicking
Apply or OK.
Workaround: In order for the new value to take effect, press the
Enter key before you click Apply or OK.
Number Description
42972 In the Case channel, if you select a field set, the field set selector
does not display the field set. This is a known issue.
44028 On Macintosh: If you click the Help menu and select About and
then click the ArcSight Copyrights... link in the “About” page, you
will get a Java Exception. This exception is generated by an issue in
the Grand-Rapid browser.
46426 When the Asset channel refreshes as new assets are added to it,
some of the assets will not appear under the following scenarios:
• If there are assets in the channel that are deleted and then
re-added or updated.
• One or more of the assets is selected and opened for edit in the
edit window and the edit window has resized the asset channel
viewer window.
49024 Using hotkeys with View Pattern and View Pattern with Filter is not
supported in this release.
49608 In a Hierarchy Map Data Monitor, once a color range is specified, you
cannot change the color mappings on the range.
Workaround: Delete the existing color mapping and create a new
one with the color mapping of your choice.
51094 On Unix systems: The drag-and-drop feature does not work in the
Console.
Workaround: Use the cut-and-paste feature instead.
Number Description
52617 The Active Channel “Slide Show” feature (View > Slide Show >
Start) maximizes the viewer to full screen and takes over the entire
screen space. If you are working on multiple monitors, the slide
show will take over your primary display.
Workaround: If you have started the slide show from the Console,
and want to exit out of it, press the Esc (Escape) key to stop it. This
will return your Console to normal viewing mode and close the
maximized channel windows. If possible, please avoid using this
feature in this release.
Number Description
53435 When you set the Schedule Frequency for a report, the Next Run
Time field displays incorrectly in the Editor.
Even though the time displays incorrectly, the report runs at the
time specified in the editor.
56865 On Linux only: If you right-click on the port field in a channel and
select Integration Commands->Portinfo (Linux) you will get an error.
59649 Linux and Mac OS: Logger integration commands are not available
from the context menu on the Channels tab of the ArcSight Console.
Workaround: To run Logger integration command for these
operating systems, use an external browser.
61659 When a user tries to modify a case while a case channel is open and
an inline filter is applied, no data appears.
Workaround: To successfully display available data, refresh the
case channel.
See also, 56093.
61713 On ESM 4.5 SP1, if the "\" character is used on a rule condition, the
rule fails to compile. An error message appears. 4.0 SP3 does not
have this problem. As a result, if you perform an upgrade from 4.0
SP3 to 4.5, all the rules that have "\" in the their conditions are
broken.
Workaround: Specify the condition in a filter and use the filter in
the rule condition (instead of specifying this condition directly in the
rule.)
ArcSight Web
Number Description
25667 If you create a Last State Data Monitor and add it to the dashboard
in table and tile format, it will be rendered in tile format only when
you view it in ArcSight Web. However, it renders correctly in the
Console.
43254 Occasionally, when you drill down into the event details in a live
channel, the details display for the event, but if you select another
event and try to drill down to see its details, they do not appear.
Workaround: Restart ArcSight Web.
Number Description
43327 ArcSight Web channels do not support sorting by a time field other
than the one chosen as the channel time stamp. For example, a
channel in ArcSight Web cannot use Manager Receipt Time as the
timestamp and End Time as the sorting timestamp. Attempting to
use such a channel in ArcSight Web produces an error.
Workaround: Use ArcSight Console to modify the channel sort
column and then use it in ArcSight Web.
46969 When you use ArcSight Web with the Firefox web browser, you might
encounter an error if you refresh an Active Channel.
56258 When you create a Case, if you set the Estimated Resource Time, it
does not get set.
Workaround: Define this setting on the Console. See the Console
online Help for steps to do this.
DST Issues
Number Description
54713 If you had scheduled a report to run every two hours before the
start of Daylight Saving Time and scheduled the first run to occur at
an even numbered hour (for example 2:00 pm), once DST begins,
the scheduled run for this report will occur on odd numbered hours
(for example 1:00 am, 3:00 am, etc.). The interval will continue to
be every 2 hours.
54749 Depending on your time zone, you may see your scheduled tasks
55835 running off by 15 minutes to an hour. For example, scheduled tasks
will run 15 minutes early in America/Guyana, whereas in
Asia/Bahrain or Europe/London it will run one hour early, etc.
Analytics
Number Description
28604 ArcSight ESM does not drop old Session List partitions automatically.
Since the Session List entries are relatively small in number
compared to events, this data usually does not need a lot of
database space and need not be deleted.
31413 By default, reports with merged section column values will only print
each value for the column once, vertically aligned in the center of
the listing for that column value.
Workaround: To improve readability when sections contain more
than a page of data, we recommend setting the vertical alignment of
the relevant section column to the top. This causes the value of the
section to appear at the top of the relevant section, making the
report more readable.
38832 When you display Assets in an Asset Channel, the Device Zone
Network Name column does not get populated in the Grid view.
Workaround: To view the details of an Asset, click the right-facing
arrow in the first column to open the Asset Detail box.
39407 The Scheduled Time column in the Scheduled Runs view covers both
time ranges for runs that have already occurred and for runs that
are pending. As a result, you will see some discrepancy in the time
ranges shown in the column. For example, against the runs that
have already occurred you will see the lower end of the time range
(For trends set to run hourly, if the time range is between 1:00 pm –
2:00 pm you will see 1:00 pm). The pending runs show the upper
range (if the time range is between 1:00 pm – 2:00 pm you will see
2:00 pm). Trends that have already occurred will have a time
difference that reflects the trend query schedule (e.g., one hour for
hourly queries), while the pending runs will have a time difference
that reflects the overall task schedule (e.g., 24 hours if run once a
day).
39932 When applying a new channel to verify rules, the generated events
may not show up in the channel correctly because the correlated
events don’t match the filter.
Workaround: Add an OR condition to the channel filter as
“sessionID > 0” when you specify a filter for testing rules with
replay.
Number Description
43456 When creating an asset, assigning a category to it, and adding the
asset to a new package, uninstalling the package results in the
category also being deleted.
Workaround:
1 Create a package and explicitly include the resources that should
never be deleted in the package.
2 Export that package.
If the resources under the parent groups change, then that package
may need to be exported periodically.
43912 If you import the content of an older package into an existing newer
package, the contents from the two packages are merged. The
resulting package will consist of contents from both packages. The
relationships are merged, but the attributes are picked up from the
old package.
Workaround: Export the new package to a bundle file so that you
can recover if needed. Then delete the new package before
importing the old one.
Number Description
54507 Verify Rules with Events (replay with rules) does not work for these
types of active lists:
• an event-based active list with values
• a field-based active list with values, where all fields are mapped
to event fields
Verify Rules with Events does work for other types of active lists.
Also, valid active lists work properly with real-time rules when they
are deployed, including the two types of active lists described above.
55314 Variable names that contain dashes or hyphens (-) in the name do
not work properly when included on the right side of a comparison in
a condition statement.
For example, consider a Rule with a condition that compares the JME
argument sqrt(4) to a variable named abc-cde, where the value of
abc-cde is: add (2.0,3.0).
This rule will not trigger successfully, and the logs will show an
exception indicating ESM is “unable to evaluate rule”.
Workaround: As a best practice, do not use dashes or hyphens (-)
in variable names. Underscores (_) are acceptable in variable
names, but upper and lower case letters only are best.
56345 If your query uses the getSessionData variable to join a session list
with an active list you will get an error when you try to run the
report or view the channel.
59649 Linux and Mac OS: Logger integration commands are not available
from the context menu on the Channels tab of the ArcSight Console.
Workaround: To run Logger integration command for these
operating systems, use an external browser.
61576 When using a Query Viewer, if you drill down on a resource reference
field, the drilldown menu may not show up. You may also see an
exception.
61885 ESM does not support the modification of the Active List schema (the
ArcSight Console prevents this action). Importing a new schema for
an Active List through archives can lead to inconsistencies in the
Active List schema definition and table.
Workaround: If you feel that you have inadvertently modified your
Active List schema by importing an Active List with the same URI but
different schema, please call ArcSight Customer Support to correct
this issue.
Connectors
Number Description
Exiting...
Workaround: Use the sendlogs feature by clicking
Tools->Sendlogs in the Console.
Localization
This section provides information on related open issues.
Number Description
45090 A field (Data Monitor Type) in the Attribute tab of Data Monitor
Editor is only partially displayed.
Workaround: Expand the Inspect/Edit pane until you see the full
text in the Data Monitor Type field.
45278 On Solaris, when you generate a report in the PDF format, the
contents of the report appear to be garbled.
Workaround: Generate the report in a format other than PDF.
Number Description
48266 The French version of the Console may display double quotes
instead of single quotes when displaying l’ or d’ (for example, l" or d"
instead of l' or d')